Acceptable Use Policy
What you may not do with the identity service, and what happens if you do.
Version 1.0 In force since September 2, 2026 Updated September 2, 2026
This policy is part of the Terms of Service. It exists because an identity provider is trusted by the people who type their password into it: the sign-in pages we host share one domain, one reputation and one set of rate limits across every tenant, and one customer’s abuse becomes every customer’s problem.
1. Identity and deception
- Do not use the platform for phishing. A hosted sign-in page may carry your brand, your logo and your colours — never those of another company, product or institution, and never a look designed to be mistaken for one.
- Do not create a tenant to harvest credentials, to run a fraud, to launder money, to evade a ban elsewhere, or to authenticate users of a service that is itself unlawful.
- Do not misrepresent who operates your applications. The name and links shown on the consent screen must identify you truthfully.
2. Applications, secrets and tokens
- Keep client secrets secret: out of source code, out of browsers, out of mobile apps. Public clients use PKCE and no secret, and that is the only correct way to ship one.
- Register only redirect URIs you control. A redirect URI you do not control is an open door to someone else’s account.
- Use tokens only within the scopes and audiences they were issued for, and do not pass an end user’s token to a party they did not authorise.
- Do not resell access to the service, or use it to build a competing identity product, without a written agreement.
3. Technical limits and security testing
- Respect the published rate limits on sign-in, registration, second-factor verification and the API. They protect every tenant against brute force; spreading requests across IP addresses, tenants or accounts to get around them is a breach, not an optimisation.
- Do not attempt to reach another tenant’s data, to bypass isolation or authentication, to forge or replay tokens, or to interfere with anyone else’s use of the service.
- Security testing against your own tenant, with your own accounts, is welcome. Testing anything else — other tenants, the control plane, our infrastructure — requires our written authorisation first. Report what you find to security@quathos.com: our Security page describes what we ask of researchers and what we commit to in return, and we do not threaten people who help us.
4. Content and data
- No unlawful content, no content that infringes someone else’s rights, and no material that harasses or endangers a person — on your sign-in page, in your application names, or in the profile fields you define.
- Do not store in user profiles, custom claims or metadata the categories of data the platform was not built for: health records, biometrics, government identity documents, payment card numbers, or anything covered by HIPAA or PCI DSS. An identity provider needs to know who a person is, not their medical history.
- Have a lawful basis for every user you import or create, and give them your own privacy notice. We are your processor; the obligation to inform them is yours.
5. Enforcement
We would rather warn you than shut you down. For most breaches we contact you first and give you a chance to fix it. Where the abuse is severe, ongoing, or puts people at immediate risk — active phishing, credential harvesting, an attack on isolation — we suspend first and explain immediately after. Your right to the return of your tenant’s data, described in the Terms and in the Data Processing Addendum, survives any suspension. Report abuse to security@quathos.com.